Secure Firewall ASA and FTD

CVE-2024-20361: A vulnerability in the Object Groups for Access Control Lists (ACLs) feature of Cisco Firepower Management…

A vulnerability in the Object Groups for Access Control Lists (ACLs) feature of Cisco Firepower Management Center (FMC) Software could allow an unauthenticated, remote attacker to bypass configured access controls on managed devices that are running Cisco Firepower Threat Defense (FTD) Software.

Published

ExploitedNot in CISA KEV
Ransomware useNot reportedPer CISA
SeverityMEDIUMCVSS 3.1 5.8
EPSS0.40%Chance of exploitation in 30 days
Public exploitNot tracked
FixNot yet

Automatic summary from the vendor's CVE record. We haven't written a full analysis of this vulnerability yet.

Affected and fixed versions

Product / branchFixed in
Cisco Firepower Management Center 7.1See the advisory
Cisco Firepower Management Center 7.1See the advisory
Cisco Firepower Management Center 7.1See the advisory
Cisco Firepower Management Center 7.1See the advisory
Cisco Firepower Management Center 7.2See the advisory
Cisco Firepower Management Center 7.2See the advisory
Cisco Firepower Management Center 7.2See the advisory
Cisco Firepower Management Center 7.2See the advisory
Cisco Firepower Management Center 7.2See the advisory
Cisco Firepower Management Center 7.2See the advisory
Cisco Firepower Management Center 7.3See the advisory
Cisco Firepower Management Center 7.3See the advisory
Cisco Firepower Threat Defense Software N/ASee the advisory

Always confirm against the vendor advisory, which lists every fixed hotfix.

What it is

A vulnerability in the Object Groups for Access Control Lists (ACLs) feature of Cisco Firepower Management Center (FMC) Software could allow an unauthenticated, remote attacker to bypass configured access controls on managed devices that are running Cisco Firepower Threat Defense (FTD) Software. This vulnerability is due to the incorrect deployment of the Object Groups for ACLs feature from Cisco FMC Software to managed FTD devices in high-availability setups. After an affected device is rebooted following Object Groups for ACLs deployment, an attacker can exploit this vulnerability by sending traffic through the affected device. A successful exploit could allow the attacker to bypass configured access controls and successfully send traffic to devices that are expected to be protected by the affected device.

Exploitation

The Cisco Product Security Incident Response Team (PSIRT) is not aware of any public announcements or malicious use of the vulnerability that is described in this advisory.

Sources

KEV status, EPSS score and vendor data refreshed automatically, last on 11 Oct 2026.

Get alerts

A notification when we publish a new analysis or a covered vendor gets a new actively exploited CVE. No account, no email.